Imagaine for a moment what it would be like if during every second of work during every day of the week each and every thing you did was accompanied by a corresponding design exercise along the lines of "okay, but what if it crashes right then." Now that would sure produce some "software with good error handling", now wouldn't it. That is crash-only software.
In complex systems, there's always the assumed potential for untoward behavior from unanticipated recovery environments; the handling of recovery can be a bigger problem than a complete failure.
In these environments, clean failures are preferable.
And staging the recovery processing can be preferred. This goes as far as staging application start-up and sequencing the component server reboots manually. Yes, manually.